▲ 550 ▼ NIST proposes barring some of the most nonsensical password rules (arstechnica.com) submitted 2 years ago by Amicitas@lemmy.world to c/technology@lemmy.world 165 comments fedilink hide all child comments Here is the text of the NIST sp800-63b Digital Identity Guidelines.
[–] pivot_root@lemmy.world 10 points 2 years ago (1 child) Sounds like my bank. permalink fedilink source parent hideshow 2 child comments replies: [–] orclev@lemmy.world 5 points 2 years ago Banks usually have the absolute worst password policies. It's typically because their backend is some crusty mainframe from the 80s that limits inputs to something absurdly insecure by today's standards and they've kicked the upgrade can down the road for so long now that it's a staggeringly monumental task to rewrite it all. Thankfully most of them have upgraded at this point, but every now and then you still find one that's got ridiculous limits like a maximum password length of 8 and only alphanumeric characters (with no 2FA obviously). permalink fedilink source parent
[–] orclev@lemmy.world 5 points 2 years ago Banks usually have the absolute worst password policies. It's typically because their backend is some crusty mainframe from the 80s that limits inputs to something absurdly insecure by today's standards and they've kicked the upgrade can down the road for so long now that it's a staggeringly monumental task to rewrite it all. Thankfully most of them have upgraded at this point, but every now and then you still find one that's got ridiculous limits like a maximum password length of 8 and only alphanumeric characters (with no 2FA obviously). permalink fedilink source parent